Pwn2Own Toronto 2022: on the first day, participants earned $400K total for new exploits targeting Samsung Galaxy S22, printers, routers, and NAS devices
what you need to know James Sebree / Tenable TechBlog : NETGEAR Router Network Misconfiguration Hisan Kidwai / Android Headlines : Galaxy S22 falls for two zero-day attacks during one event Tyler Lee / Phandroid : The Samsung Galaxy S22 was hacked twice in a single day Tweets: @thezdi : STAR Labs was able to execute their improper input validation attack on their 3rd try against the Samsung Galaxy S22. They earn $50K and 5 Master of Pwn points. #P2OToronto #Pwn2Own The team got a great video of the exploit attempt: https://youtube.com/... https://twitter.com/...
Context & Ripple Effects
Pwn2Own had already demonstrated that high-value consumer targets were reachable: Mobile Pwn2Own 2017 breaches covered iPhone, Samsung and Huawei devices, while Pwn2Own Vancouver 2022 exploits extended the contest’s focus across Microsoft, Ubuntu and Tesla products. Toronto puts a Galaxy handset alongside printers, routers and NAS devices in the same testing arena.
The two Galaxy S22 zero-days show that a flagship mobile device was not insulated from the broader consumer-device attack surface. Later Toronto coverage recorded 58 zero-days and repeated Galaxy S23 compromises, reinforcing that the event was surfacing recurring issues across successive device generations.
First-order effects
- Samsung must remediate the two Galaxy S22 flaws disclosed through the contest; STAR Labs’ improper-input-validation exploit specifically identifies an attack class that its security team must address.
- Manufacturers of the targeted printers, routers and NAS devices face an immediate review-and-patch cycle, while NETGEAR’s reported network misconfiguration puts router configuration security under scrutiny.
Second-order effects
- Enterprise and consumer buyers using the affected device categories gain a concrete reason to prioritize firmware and configuration updates, rather than treating routers and NAS appliances as set-and-forget equipment.
- The $400,000 first-day payout strengthens Pwn2Own’s role as a disclosure channel, competing for researcher attention with other routes for reporting high-impact consumer-device vulnerabilities.
Third-order effects
- Repeated contest compromises of Samsung flagships, from the Galaxy S22 to the later Galaxy S23 findings, point to security maintenance becoming a continuing product obligation across hardware generations rather than a one-time launch requirement.
- If contests continue to reward exploits across phones and home-network equipment together, vendors will face pressure to secure the connected-device chain as an ecosystem, including device software and default network configuration.
The trend: Pwn2Own is increasingly treating consumer security as a connected-device problem, where phones, routers, storage and peripherals all require recurring vulnerability research and remediation.